|
|
@@ -1,54 +0,0 @@
|
|
|
-[ ca ]
|
|
|
-default_ca = testca
|
|
|
-
|
|
|
-[ testca ]
|
|
|
-dir = .
|
|
|
-certificate = $dir/cacert.pem
|
|
|
-database = $dir/temp/index.txt
|
|
|
-new_certs_dir = $dir/temp
|
|
|
-private_key = $dir/temp/cakey.pem
|
|
|
-serial = $dir/temp/serial
|
|
|
-
|
|
|
-default_crl_days = 7
|
|
|
-default_days = 365
|
|
|
-default_md = sha256
|
|
|
-
|
|
|
-policy = testca_policy
|
|
|
-x509_extensions = certificate_extensions
|
|
|
-
|
|
|
-[ testca_policy ]
|
|
|
-commonName = supplied
|
|
|
-stateOrProvinceName = optional
|
|
|
-countryName = optional
|
|
|
-emailAddress = optional
|
|
|
-organizationName = optional
|
|
|
-organizationalUnitName = optional
|
|
|
-domainComponent = optional
|
|
|
-
|
|
|
-[ certificate_extensions ]
|
|
|
-basicConstraints = CA:false
|
|
|
-
|
|
|
-[ req ]
|
|
|
-default_bits = 2048
|
|
|
-default_keyfile = ./temp/cakey.pem
|
|
|
-default_md = sha256
|
|
|
-prompt = yes
|
|
|
-distinguished_name = root_ca_distinguished_name
|
|
|
-x509_extensions = root_ca_extensions
|
|
|
-
|
|
|
-[ root_ca_distinguished_name ]
|
|
|
-commonName = hostname
|
|
|
-
|
|
|
-[ root_ca_extensions ]
|
|
|
-basicConstraints = CA:true
|
|
|
-keyUsage = keyCertSign, cRLSign
|
|
|
-
|
|
|
-[ client_ca_extensions ]
|
|
|
-basicConstraints = CA:false
|
|
|
-keyUsage = digitalSignature
|
|
|
-extendedKeyUsage = 1.3.6.1.5.5.7.3.2
|
|
|
-
|
|
|
-[ server_ca_extensions ]
|
|
|
-basicConstraints = CA:false
|
|
|
-keyUsage = keyEncipherment
|
|
|
-extendedKeyUsage = 1.3.6.1.5.5.7.3.1
|